
Cloud Vulnerability DB
A community-led vulnerabilities database
The CVE-2025-39560 is a Missing Authorization vulnerability affecting the Live Forms WordPress plugin versions through 4.8.4. The vulnerability was discovered and disclosed on April 16, 2025, by security researcher Nguyen Xuan Chien (Patchstack, WPScan).
The vulnerability is classified as a Missing Authorization issue (CWE-862) with a CVSS v3.1 base score of 5.4 (Medium). The vulnerability allows authenticated attackers with Subscriber-level access and above to perform unauthorized actions due to missing capability checks on certain functions (WPScan, Patchstack).
The vulnerability enables authenticated users with Subscriber-level privileges to perform actions beyond their intended authorization level, potentially leading to unauthorized access and manipulation of data (Patchstack).
The vulnerability has been fixed in version 4.8.5 of the Live Forms plugin. Users are advised to update to this version or later to address the security issue (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."